{"id":328434,"date":"2026-08-13T00:01:54","date_gmt":"2026-08-12T22:01:54","guid":{"rendered":"https:\/\/borncity.com\/blog\/?p=328434"},"modified":"2026-08-13T00:33:43","modified_gmt":"2026-08-12T22:33:43","slug":"wordpress-7-0-4-verfuegbar-12-august-2026","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2026\/08\/13\/wordpress-7-0-4-verfuegbar-12-august-2026\/","title":{"rendered":"WordPress 7.0.4 verf\u00fcgbar (12. August 2026)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2014\/07\/wp_thumb.jpg\" alt=\"\" width=\"64\" height=\"64\" align=\"left\" \/>Kurze Information: Am 12. August 2026 haben die Entwickler (6 Tage nach dem Release von <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-3\/\" target=\"_blank\" rel=\"noopener\">WordPress 7.0.3<\/a>) das n\u00e4chste Update nachgeschoben. <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-4\/\" target=\"_blank\" rel=\"noopener\">WordPress 7.0.4<\/a> wurde f\u00fcr die \u00d6ffentlichkeit freigegeben und wurde mir gestern in den Blogs zum Update angeboten. Es ist ein Sicherheitsupdate, welches z\u00fcgig installiert werden sollte &#8211; einige meiner Blogs wurden per Auto-Update aktualisiert.<\/p>\n<p><!--more--><\/p>\n<p>Die Sicherheitsfixes von WordPress 7.0.4 sind in <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-0-4\/\" target=\"_blank\" rel=\"noopener\">diesem Dokument<\/a> beschrieben. Da diese Version mehrere Sicherheitskorrekturen enth\u00e4lt, wird empfohlen, Instanzen umgehend zu aktualisieren. Die neue Version fixt eine vom Team von pwn.ai gemeldete Sicherheitsl\u00fccke<span style=\"font-style: italic;\">, <\/span>die die Ausf\u00fchrung von Remote-Code durch \u201eAuthor+\" nach Authentifizierung \u00fcber das Hochladen b\u00f6sartiger Dateien auf Websites erm\u00f6glicht, die Imagick und Ghostscript verwenden.<\/p>\n<p>Das WordPress Team hat auch einen Backport f\u00fcr \u00e4lter WordPress-Versionen vorgenommen:<\/p>\n<ul class=\"wp-block-list\">\n<li>WordPress 6.9 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-9-7\/\">Version 6.9.7<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.8 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-8-8\/\">Version 6.8.8<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.7 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-7-7\/\">Version 6.7.7<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.6 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-6-7\/\">Version 6.6.7<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.5 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-5-10\/\">Version 6.5.10<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.4 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-4-10\/\">Version 6.4.10<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.3 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-3-10\/\">Version 6.3.10<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.2 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-2-11\/\">Version 6.2.11<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.1 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-1-12\/\">Version 6.1.12<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 6.0 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-0-14\/\">Version 6.0.14<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.9 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-9-16\/\">Version 5.9.16<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.8 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-8-15\/\">Version 5.8.15<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.7 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-7-17\/\">Version 5.7.17<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.6 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-6-19\/\">Version 5.6.19<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.5 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-5-20\/\">Version 5.5.20<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.4 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-4-21\/\">Version 5.4.21<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.3 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-3-23\/\">Version 5.3.23<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.2 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-2-26\/\">Version 5.2.26<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.1 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-1-24\/\">Version 5.1.24<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 5.0 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-0-27\/\">Version 5.0.27<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 4.9 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-9-31\/\">Version 4.9.31<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 4.8 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-8-30\/\">Version 4.8.30<\/a>\u00a0has been released containing a fix.<\/li>\n<li>WordPress 4.7 is affected by this vulnerability.\u00a0<a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-4-7-35\/\">Version 4.7.35<\/a>\u00a0has been released containing a fix.<\/li>\n<\/ul>\n<p>F\u00fcr WordPress 4.6 und fr\u00fchere Versionen werden keine Sicherheitsupdates mehr bereitgestellt.<\/p>\n<p>Ein Blog-Leser hatte gestern im Diskussionsbereich bereits mit folgendem Text auf dieses Update hingewiesen (danke):<\/p>\n<blockquote><p>Das n\u00e4chste schnell schnell WordPress Security Update 7.0.4 mit R\u00fcckportierung bis in den WordPres 4.7.x Zweig:<\/p>\n<p><a href=\"https:\/\/wordpress.org\/news\/2026\/08\/wordpress-7-0-4-release\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">https:\/\/wordpress.org\/news\/2026\/08\/wordpress-7-0-4-release\/<\/a><\/p>\n<p>Warum man das nicht selbst rausfindet sondern alles von externen Firmen entdeckt wird, das weiss nur WordPress selbst\u2026<\/p>\n<p>PS. Der Rollout der 6.8.x und 6.6.x R\u00fcckportierungen wurde augenscheinlich wieder gestoppt, kam nur bei einem Teil unserer Seiten an, der Rest behauptet jetzt mit der \u00e4lteren Version in diesem Pfad aktuell zu sein.<\/p><\/blockquote>\n<p>In einem zweiten Kommentar kam dann noch folgender Hinweis:<\/p>\n<blockquote><p>Die \/blog\/ WordPress Installation hier ist wohl auch von der zwischenzeitlichen Rollout Unterbrechung betroffen, sie l\u00e4uft derzeit noch mit 7.0.3 w\u00e4hrend die Hauptdomain bereits mit 7.0.4 l\u00e4uft.<\/p><\/blockquote>\n<p>Hier kann ich zur Aufkl\u00e4rung beitragen: Nein, es gab keine \"Rollout Unterbrechung\" seitens WordPress. Ich hatte den Hinweis auf das Update schon einige Zeit vor dem Absetzen der Kommentare gesehen und auch einige Benachrichtigungen von weiteren Blogs erhalten, die ein Auto-Update auf die 7.0.4 durchgef\u00fchrt haben.<\/p>\n<p>Aber bei den beiden IT-Blogs auf borncity.com, die von mir bef\u00fcllt werden, verfolge ich einen gestuften Ansatz:<\/p>\n<ul>\n<li>Kein Auto-Update des WordPress-Cores und der Plugins<\/li>\n<li>Ich fahre die Updates zu Zeiten, wo ich ggf. jemand beim neuen Eigent\u00fcmer erreichen kann.<\/li>\n<li>Als Test werden Blogs auf borncity.eu aktualisiert, da ich dort die vollst\u00e4ndige Kontrolle besitze.<\/li>\n<li>Als n\u00e4chstes kommt der englische IT-Blog beim Update dran &#8211; wenn der mal einen Tag kaputt ist, ist der Schaden gering.<\/li>\n<li>Als letzter Blog wird immer der IT-Blog hier aktualisiert.<\/li>\n<\/ul>\n<p>Damit habe ich die Hoffnung, die IT-Blogs nicht ungewollt durch irgendwelche verungl\u00fcckten Updates ins digitale Nirvana zu schie\u00dfen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kurze Information: Am 12. August 2026 haben die Entwickler (6 Tage nach dem Release von WordPress 7.0.3) das n\u00e4chste Update nachgeschoben. WordPress 7.0.4 wurde f\u00fcr die \u00d6ffentlichkeit freigegeben und wurde mir gestern in den Blogs zum Update angeboten. Es ist &hellip; <a href=\"https:\/\/borncity.com\/blog\/2026\/08\/13\/wordpress-7-0-4-verfuegbar-12-august-2026\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426,7459,1574],"tags":[4328,4315,4349],"class_list":["post-328434","post","type-post","status-publish","format-standard","hentry","category-sicherheit","category-software","category-wordpress","tag-sicherheit","tag-update","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=328434"}],"version-history":[{"count":3,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328434\/revisions"}],"predecessor-version":[{"id":328437,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328434\/revisions\/328437"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=328434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=328434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=328434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}